52% of Serious Vulnerabilities We Find are Related to Windows 10

23/01/2024 0 Comments 0 tags

We analyzed 2,5 million vulnerabilities we discovered in our customer’s assets. This is what we found. Digging into the data The dataset we analyze here is representative of a subset

MavenGate Attack Could Let Hackers Hijack Java and Android via Abandoned Libraries

23/01/2024 0 Comments 0 tags

Several public and popular libraries abandoned but still used in Java and Android applications have been found susceptible to a new software supply chain attack method called MavenGate. “Access to

North Korean Hackers Weaponize Fake Research to Deliver RokRAT Backdoor

23/01/2024 0 Comments 0 tags

Media organizations and high-profile experts in North Korean affairs have been at the receiving end of a new campaign orchestrated by a threat actor known as ScarCruft in December 2023. “ScarCruft has

Apache ActiveMQ Flaw Exploited in New Godzilla Web Shell Attacks

22/01/2024 0 Comments 0 tags

Cybersecurity researchers are warning of a “notable increase” in threat actor activity actively exploiting a now-patched flaw in Apache ActiveMQ to deliver the Godzilla web shell on compromised hosts. “The

Chinese Hackers Silently Weaponized VMware Zero-Day Flaw for 2 Years

20/01/2024 0 Comments 0 tags

An advanced China-nexus cyber espionage group previously linked to the exploitation of security flaws in VMware and Fortinet appliances has been linked to the abuse of a critical vulnerability in

Invoice Phishing Alert: TA866 Deploys WasabiSeed & Screenshotter Malware

20/01/2024 0 Comments 0 tags

The threat actor tracked as TA866 has resurfaced after a nine-month hiatus with a new large-volume phishing campaign to deliver known malware families such as WasabiSeed and Screenshotter. The campaign, observed earlier

Microsoft’s Top Execs’ Emails Breached in Sophisticated Russia-Linked APT Attack

20/01/2024 0 Comments 0 tags

Microsoft on Friday revealed that it was the target of a nation-state attack on its corporate systems that resulted in the theft of emails and attachments from senior executives and

CISA Issues Emergency Directive to Federal Agencies on Ivanti Zero-Day Exploits

20/01/2024 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday issued an emergency directive urging Federal Civilian Executive Branch (FCEB) agencies to implement mitigations against two actively exploited zero-day flaws in Ivanti

Npm Trojan Bypasses UAC, Installs AnyDesk with “Oscompatible” Package

20/01/2024 0 Comments 0 tags

A malicious package uploaded to the npm registry has been found deploying a sophisticated remote access trojan on compromised Windows machines. The package, named “oscompatible,” was published on January 9,

Preventing Data Loss: Backup and Recovery Strategies for Exchange Server Administrators

20/01/2024 0 Comments 0 tags

In the current digital landscape, data has emerged as a crucial asset for organizations, akin to currency. It’s the lifeblood of any organization in today’s interconnected and digital world. Thus,